312-85 · Question #48
A threat analyst obtains an intelligence related to a threat, where the data is sent in the form of a connection request from a remote host to the server. From this data, he obtains only the IP…
The correct answer is C. Distributed Denial-of-Service (DDoS) attack. Option C is correct because the scenario describes the hallmark pattern of a DDoS attack: multiple connection requests originating from different geographic locations flooding a single server, causing performance degradation - this is precisely distributed, volumetric…
Question
A threat analyst obtains an intelligence related to a threat, where the data is sent in the form of a connection request from a remote host to the server. From this data, he obtains only the IP address of the source and destination but no contextual information. While processing this data, he obtains contextual information stating that multiple connection requests from different geo- locations are received by the server within a short time span, and as a result, the server is stressed and gradually its performance has reduced. He further performed analysis on the information based on the past and present experience and concludes the attack experienced by the client organization. Which of the following attacks is performed on the client organization?
Options
- ADHCP attacks
- BMAC spoofing attack
- CDistributed Denial-of-Service (DDoS) attack
- DBandwidth attack
How the community answered
(32 responses)- A3% (1)
- B3% (1)
- C84% (27)
- D9% (3)
Explanation
Option C is correct because the scenario describes the hallmark pattern of a DDoS attack: multiple connection requests originating from different geographic locations flooding a single server, causing performance degradation - this is precisely distributed, volumetric denial-of-service behavior. The intelligence processing pipeline described (raw IP data → contextual enrichment → behavioral analysis) mirrors how analysts attribute DDoS campaigns.
Why the distractors are wrong:
- A (DHCP attacks) target IP address assignment on a local network - they don't involve connection floods from multiple external geo-locations.
- B (MAC spoofing) is a Layer 2 attack that manipulates hardware addresses within a local network segment; it doesn't explain cross-geo traffic overwhelming a server.
- D (Bandwidth attack) is a subcategory of DDoS (specifically volumetric DDoS), not a standalone attack type separate from it - the broader, more precise answer is C.
Memory tip: Remember the three D's - Distributed (many sources), Different locations (geo-spread), Degradation (server stress). When all three appear together in a scenario, that's DDoS every time.
Topics
Community Discussion
No community discussion yet for this question.